Andrea Lago Quijada

Cybersecurity governance, translated into business decisions.

Senior Cybersecurity Consultant · Governance, Risk & Compliance

I connect regulation, technology risk, data and business in international, highly regulated environments.

Profile

Legal rigour.
Technology risk.
Business perspective.

My legal training and prior practice shaped how I interpret requirements, assess evidence and communicate with precision. I now apply that foundation to cybersecurity governance, technology risk and executive reporting.

Alongside my consulting career, I develop independent digital and business initiatives, working from proposition and positioning through to functional website delivery and operating-model design. This practical perspective complements how I work across business, governance and technical teams: bringing structure to complexity and turning information into action.

Expertise

Where regulation, risk, technology and business meet.

01

Cybersecurity Governance & GRC

Control and evidence reviews, compliance assessments, gap analysis, governance documentation and action-plan follow-up.

02

Technology Risk & Service Governance

KPI and KRI monitoring and analysis, deviation management, accountability and traceability across service-governance processes.

03

Executive Reporting, Dashboards & Data

Analysis of 100+ risk indicators, functional dashboard review, data-quality follow-up and executive communication.

04

Legal Practice & Regulatory Analysis

Legal advice, case preparation, regulatory research and drafting, with a practical understanding of how requirements translate into controls, evidence and governance.

05

Digital & Business Development

Developing independent digital initiatives from value proposition and service design to brand positioning, functional website delivery and practical operating models.

Complementary capabilities: applied AI and automation · project and team management · stakeholder coordination · executive communication · legal technology · SEO fundamentals

Professional examples are anonymised and limited to non-confidential information. Independent initiatives are presented at capability level.

Experience

A legal foundation. A cybersecurity trajectory.

Deloitte

Senior Cybersecurity Consultant

Governance, technology risk, executive reporting and cross-functional coordination within an international, highly regulated financial environment.

Deloitte

Cybersecurity Consultant · Cyber Transformation Management & Compliance

Risk and service indicators, deviation analysis, data quality, functional dashboard review, compliance initiatives and coordination with distributed technical and business teams.

Distrito de Abogados

Lawyer

Legal advice, regulatory analysis, drafting of legal documentation and preparation and follow-up of proceedings.

LAL Abogados · Criminal & Civil Department

Trainee Lawyer

Legal research, documentary analysis and support in the preparation of criminal and civil matters.

INTER PARTES S.L. · Silvia Requena Abogados

Trainee Lawyer

Early legal-practice experience focused on research, documentary review and case preparation.

How I work

From signal to accountable action.

Across cybersecurity consulting, legal work and independent initiatives, I bring structure to ambiguity and maintain a clear line from analysis to action and decision-making.

  1. Signal or requirement
  2. Analysis and validation
  3. Cause and impact
  4. Owner and action plan
  5. Target date and follow-up
  6. Executive reporting

Knowledge

Education, credentials and professional development.

Education & executive programmes

  • Executive Programme in Cybersecurity, Risk & Digital SecurityCentro de Estudios Garrigues · Oct 2023 — Mar 2024 · Grade 8.5/10
  • University Certificate in ComplianceUniversidad Europea · Feb — Apr 2024 · Grade 9.83/10
  • Master’s in Criminal Law & Criminal ProcedureUniversidad Carlos III de Madrid · Sep 2022 — Jun 2023
  • Master’s in Legal PracticeUniversitat Oberta de Catalunya · Sep 2021 — Jun 2023
  • LL.B. in Law · Academic Excellence ScholarshipUniversitat Internacional de Catalunya · 2018 — 2021

Additional training & credentials

  • Effective Project & Team ManagementSantander Open Academy · Sep 2026
  • ISO 27001 Cybersecurity Manager GuidelinesUdemy · Apr 2025
  • Legal English for Legal ProfessionalsINEAF Business School · Mar 2024
  • General English + Business Course · C1 levelSt Giles International · Aug 2022
  • First Certificate in English (FCE)Cambridge English · Apr 2017

Regulatory knowledge, frameworks & tools

Professional experience: SWIFT CSP
Assessment exposure: ISO 27001 · NIS2
Professional exposure: ENS · NIST
Working knowledge & training: GDPR · Spanish LOPDGDD · DORA · EU AI Act · ISO 27002 · ISO 31000
Tools: Power BI and Qlik functional user · ServiceNow professional functional use · Excel · PowerPoint · Microsoft 365 · CMDB environments functional consultation
Digital capabilities: applied AI and automation · functional web design and delivery · digital and business development · brand positioning · SEO fundamentals

Career direction

Ready for the next international challenge.

I am particularly interested in remote-first and international roles across Cybersecurity Governance, Information Security GRC, Technology Risk and Security Compliance.